Splunk® Enterprise Security

Detect Unknown Threats with Behavioral Analytics Service

Acrobat logo Download manual as PDF


This documentation does not apply to the most recent version of Splunk® Enterprise Security. For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Install and configure Splunk Connect for Mission Control

This feature is deprecated.
Splunk Connect for Mission Control is deprecated in the Splunk platform as of 7.1.0.

Get data into behavioral analytics service and Splunk Mission Control from Splunk Enterprise Security (ES) on Splunk Cloud Platform with Splunk Connect for Mission Control.

Work with Splunk Support to install Splunk Connect for Mission Control on your Splunk ES search head on Splunk Cloud Platform.

  1. You must install and setup Splunk ES on Splunk Cloud Platform before you can install Splunk Connect for Mission Control.
  2. Verify the installation requirements for Splunk Connect for Mission Control, such as compatible product versions and network ports that must be open.
  3. Install Splunk Connect for Mission Control.

Perform the following tasks after Splunk Connect for Mission Control is installed:

  1. Disable the Enable/Disable Splunk Connect for Mission Control's ingestion components modular input on all search heads to prevent assets and identities from being exported every 15 minutes instead of every 24 hours.
  2. Make sure the Behavior Analytics - Forward Risk Data Model Events - Ingestion search is enabled.

Next Step: See Import assets and identities data from Splunk ES on Splunk Cloud Platform into behavioral analytics service.

Limits

  • The export limit for assets and identities data is 1 million entities, even if you have more than 1 million entities.
  • The export frequency that we are advertising today is 24 hours. However, customer can trigger the export by disabling and enabling the exporters. As part of these changes, we won't allow any exports within 4 hour interval (even if the customer disable/enable).
Last modified on 28 November, 2022
PREVIOUS
Enable or disable a detection for a tenant
  NEXT
Import assets and identities data from Splunk ES on Splunk Cloud Platform into behavioral analytics service

This documentation applies to the following versions of Splunk® Enterprise Security: 7.0.1, 7.0.2


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters